Categories: Cyber Security News

NIST Shifts to Risk-Based NVD Model as CVE Submissions Surge 263% Since 2020

The National Institute of Standards and Technology (NIST) has officially updated how it processes vulnerabilities in the National Vulnerability Database (NVD).

According to an April 15, 2026 announcement, NIST is abandoning its comprehensive analysis approach in favor of a targeted, risk-based model.

This shift ensures security teams receive timely intelligence on high-impact threats. At the same time, NIST manages an overwhelming volume of vulnerability reports.

The primary driver behind this major operational change is a massive increase in Common Vulnerabilities and Exposures (CVE) submissions.

NIST reports a staggering 263% surge in CVEs between 2020 and 2025. While the agency successfully added enrichment details such as severity scores and affected product lists to nearly 42,000 CVEs last year, this 45% productivity increase was not enough to keep pace.

The submission rate continues to accelerate, with the first quarter of 2026 seeing a 33% jump compared to the same period last year.

New Targeted Prioritization Criteria

To effectively manage this workload, NIST is no longer attempting to enrich every submitted CVE immediately. Instead, the NVD program will prioritize vulnerabilities that pose the greatest systemic risk to organizations.

Starting immediately, NIST will focus its enrichment resources on the following categories:

  • Vulnerabilities are listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, which analysts aim to process within one business day.
  • Security flaws affecting software utilized within federal government agencies.
  • Vulnerabilities involving critical software as defined by Executive Order 14028.

Any submitted CVE that falls outside these specific parameters will still be published to the NVD but will receive a “Lowest Priority” label.

These lower-priority items will not receive immediate enrichment data. However, security professionals can request manual analysis by emailing NIST directly.

Alongside the new tiering system, NIST is eliminating duplicate efforts in severity scoring. If a CVE Numbering Authority already provides a severity score during submission, the NVD will no longer generate its own separate score by default.

Furthermore, the agency is adjusting how it handles modified CVEs. Analysts will now reanalyze only previously enriched vulnerabilities if new modifications materially affect the core enrichment data.

This streamlined approach also directly addresses the NVD’s significant processing backlog that began building in early 2024. All backlogged, unenriched CVEs published before March 1, 2026, have been moved to the “Not Scheduled” category.

NIST plans to gradually process these older submissions based on the new risk criteria as resources allow.

To maintain transparency during this transition, NIST has updated the NVD Dashboard to report real-time status labels and statistics for all CVEs accurately.

By focusing exclusively on critical flaws and reducing duplicate administrative work, the agency intends to stabilize current NVD operations while dedicating resources to developing automated systems for long-term sustainability.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

The post NIST Shifts to Risk-Based NVD Model as CVE Submissions Surge 263% Since 2020 appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

LEGO Lord of the Rings Minas Tirith Set Leaks

Images showing the long-awaited LEGO Lord of the Rings Minas Tirith set have leaked online,…

12 minutes ago

Bungie’s Limited Edition Marathon Controller Just Got a Hefty Price Cut at Amazon and Walmart

Bungie’s limited-edition Marathon DualSense controller has dropped in price far quicker than expected, and it’s…

13 minutes ago

CBS Detroit Launches AR/VR-Driven Studio With Weather at 5 p.m. Today

Chief Meteorologist Ahmad Bajjey in CBS Detroit’s new AR/VR studio  CBS O&O WWJ Detroit (CBS…

19 minutes ago

EVS Launches Choreon Robotic Control Solution

The post EVS Launches Choreon Robotic Control Solution appeared first on TV News Check.

19 minutes ago

Heidi Steffen To Become President Of TitanTV

The post Heidi Steffen To Become President Of TitanTV appeared first on TV News Check.

19 minutes ago

Refreshed NAB Show Reflects An Industry In Flux

The post Refreshed NAB Show Reflects An Industry In Flux appeared first on TV News…

19 minutes ago

This website uses cookies.